ืžื”ื“ื•ืจืช ืฉืจืช http ืฉืœ Apache 2.4.49 ืขื ืคื’ื™ืขื•ื™ื•ืช ืžืชื•ืงื ื•ืช

ืคื•ืจืกื ืžื”ื“ื•ืจืช ืฉืจืช HTTP ืฉืœ Apache 2.4.49, ื”ืžืฆื™ื’ื” 27 ืฉื™ื ื•ื™ื™ื ื•ืžืชืงืŸ 5 ืคื’ื™ืขื•ื™ื•ืช:

  • CVE-2021-33193 - mod_http2 ืจื’ื™ืฉ ืœื’ืจืกื” ื—ื“ืฉื” ืฉืœ ืžืชืงืคืช "ื”ื‘ืจื—ืช ื‘ืงืฉืช HTTP", ื”ืžืืคืฉืจืช, ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ืœืงื•ื— ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“, ืœื”ืฉืชืœื‘ ื‘ืชื•ื›ืŸ ืฉืœ ื‘ืงืฉื•ืช ืžืžืฉืชืžืฉื™ื ืื—ืจื™ื ื”ืžื•ืขื‘ืจื™ื ื“ืจืš mod_proxy (ืœื“ื•ื’ืžื”, ืืชื” ื™ื›ื•ืœ ืœื”ืฉื™ื’ ืืช ื”ื›ื ืกืช ืงื•ื“ JavaScript ื–ื“ื•ื ื™ ืœื”ืคืขืœื” ืฉืœ ืžืฉืชืžืฉ ืื—ืจ ื‘ืืชืจ).
  • CVE-2021-40438 ื”ื™ื ืคื’ื™ืขื•ืช SSRF (Server Side Request Forgery) ื‘-mod_proxy, ื”ืžืืคืฉืจืช ืœื”ืคื ื•ืช ืืช ื”ื‘ืงืฉื” ืœืฉืจืช ืฉื ื‘ื—ืจ ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉืช Uri-path ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“.
  • CVE-2021-39275 - ื”ืฆืคืช ืžืื’ืจ ื‘ืคื•ื ืงืฆื™ื” ap_escape_quotes. ื”ืคื’ื™ืขื•ืช ืžืกื•ืžื ืช ื›ืฉืคื™ืจ ืžื›ื™ื•ื•ืŸ ืฉื›ืœ ื”ืžื•ื“ื•ืœื™ื ื”ืกื˜ื ื“ืจื˜ื™ื™ื ืื™ื ื ืžืขื‘ื™ืจื™ื ื ืชื•ื ื™ื ื—ื™ืฆื•ื ื™ื™ื ืœืคื•ื ืงืฆื™ื” ื–ื•. ืื‘ืœ ืชื™ืื•ืจื˜ื™ืช ื™ื™ืชื›ืŸ ืฉื™ืฉ ืžื•ื“ื•ืœื™ื ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ืฉื“ืจื›ื ื ื™ืชืŸ ืœื‘ืฆืข ืชืงื™ืคื”.
  • CVE-2021-36160 - ืงืจื™ืื” ืžื—ื•ืฅ ืœืชื—ื•ื ื‘ืžื•ื“ื•ืœ mod_proxy_uwsgi ื”ื’ื•ืจื ืœืงืจื™ืกื”.
  • CVE-2021-34798 - ื”ืคื ื™ื™ืช ืžืฆื‘ื™ืข NULL ื”ื’ื•ืจืžืช ืœืงืจื™ืกืช ืชื”ืœื™ืš ื‘ืขืช ืขื™ื‘ื•ื“ ื‘ืงืฉื•ืช ื‘ืขืœื•ืช ืžื‘ื ื” ืžื™ื•ื—ื“.

ื”ืฉื™ื ื•ื™ื™ื ื”ื‘ื•ืœื˜ื™ื ืฉืื™ื ื ื‘ื™ื˜ื—ื•ื ื™ื™ื ื”ื:

  • ืœื ืžืขื˜ ืฉื™ื ื•ื™ื™ื ืคื ื™ืžื™ื™ื ื‘-mod_ssl. ื”ื”ื’ื“ืจื•ืช "ssl_engine_set", "ssl_engine_disable" ื•-"ssl_proxy_enable" ื”ื•ืขื‘ืจื• ืž-mod_ssl ืœืžื™ืœื•ื™ ื”ืจืืฉื™ (ื”ืœื™ื‘ื”). ืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ืžื•ื“ื•ืœื™ SSL ื—ืœื•ืคื™ื™ื ื›ื“ื™ ืœื”ื’ืŸ ืขืœ ื—ื™ื‘ื•ืจื™ื ื‘ืืžืฆืขื•ืช mod_proxy. ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœืจืฉื•ื ืžืคืชื—ื•ืช ืคืจื˜ื™ื™ื, ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ื ื‘-wireshark ื›ื“ื™ ืœื ืชื— ืชืขื‘ื•ืจื” ืžื•ืฆืคื ืช.
  • ื‘-mod_proxy, ื”ื ื™ืชื•ื— ืฉืœ ื ืชื™ื‘ื™ื ืฉืœ ืฉืงืข ื™ื•ื ื™ืงืก ืฉื”ื•ืขื‘ืจื• ืœื›ืชื•ื‘ืช ื”-proxy: ื”ื•ืืฅ.
  • ื”ื•ืจื—ื‘ื• ื”ื™ื›ื•ืœื•ืช ืฉืœ ืžื•ื“ื•ืœ mod_md, ื”ืžืฉืžืฉ ืœืื•ื˜ื•ืžืฆื™ื” ืฉืœ ืงื‘ืœื” ื•ืชื—ื–ื•ืงื” ืฉืœ ืื™ืฉื•ืจื™ื ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ ACME (Automatic Certificate Management Environment). ืžื•ืชืจ ืœื”ืงื™ืฃ ื“ื•ืžื™ื™ื ื™ื ื‘ืžื™ืจื›ืื•ืช ื•ืกื™ืคืง ืชืžื™ื›ื” ืขื‘ื•ืจ tls-alpn-01 ืขื‘ื•ืจ ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ืฉืื™ื ื ืžืฉื•ื™ื›ื™ื ืœืžืืจื—ื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื.
  • ื”ื•ืกื™ืฃ ืืช ื”ืคืจืžื˜ืจ StrictHostCheck, ื”ืื•ืกืจ ืœืฆื™ื™ืŸ ืฉืžื•ืช ืžืืจื—ื™ื ืœื ืžื•ื’ื“ืจื™ื ื‘ื™ืŸ ืืจื’ื•ืžื ื˜ื™ ื”ืจืฉื™ืžื” "ืืคืฉืจ".

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”